Use the Admin Console to create lists for authenticator groups, countries, device models, geofences, IP addresses, and/or WiFI networks that are used in your Adaptive Rule conditions. If your Adaptive Rules use UAF authenticators, you must define one or more authenticator groups. Only create the other lists if your rules need them.
The table below shows the navigation path to use, and provides useful notes.
List | Admin Console Navigation |
|---|---|
Authenticator Group | Authentication > Authenticator Group It's a good idea to group authenticators by modality, for example,create a group for Android fingerprint authenticators or iOS biometric authenticators. Order the authenticators from most preferred to least preferred. After you add authenticators to your list, reorder by dragging and dropping an authenticator to a new location. If you need authenticators beyond those provided by Digipass S3, you need to add those authenticators. See Add a New Authenticator. Don't use keyboard shortcuts to select multiple authenticators. Click on each authenticator that you want, then click OK. The Admin Console remembers your selections. |
Countries | Authentication > Countries Use standard keyboard shortcuts to make contiguous or non-contiguous selections. For example, on the PC, for non-contiguous selections, hold down Ctrl as you select. Note: For web apps, see Configure the Google geocoding service. |
Device Models | Authentication > Device Models Examples of device models: "iPhone11,2", "SM-G950U", and "SM-S9010" |
Geofences | Authentication > Geofences You can use this online tool to create a geofence in the RFC 7946 JSON format. A geofence must be a GeoJSON polygon. See an example geofence JSON below this table. |
IP Addresses | Authentication > IP Addresses |
Wifi Networks | Authentication > Wifi Networks Enter the SSID (service set identifier), BSSID (basic service set identifier), or NetworkID (a unique small integer ID) to identify the network. Please note that SSID should be wrapped within double-quotes and multiple SSIDs should be separated by the comma mark. |
In addition to letters and digits, only the following characters are allowed in a list name: hyphen (-), forward slash (/), underscore (_) and space ( ).
Example Geofence JSON:
This is a geofence for an area surrounding San Jose, CA.
{
"type": "FeatureCollection",
"features": [
{
"type": "Feature",
"properties": {},
"geometry": {
"type": "Polygon",
"coordinates": [
[
[
-122.16110229492186,
37.18876668723709
],
[
-121.74087524414064,
37.18876668723709
],
[
-121.74087524414064,
37.42252593456307
],
[
-122.16110229492186,
37.42252593456307
],
[
-122.16110229492186,
37.18876668723709
]
]
]
}
}
]
}Configure the Google geocoding service
Unlike mobile apps, a web-based app can only send the latitude and longitude of the user's location, not the country code. To enable your web app to use an Adaptive Rule whose condition contains a Countries list, you need to configure the Google Geocoding API. Once that configuration is done, the Digipass S3 Server can get the country code from the latitude and longitude. You can perform this optional step post-installation.
To configure the Digipass S3 Server to use the Google Geocoding API:
Set up a Google Cloud Project to enable the Geocoding API.
Create and restrict your API key for the Google Maps Platform. Give the Digipass S3 Server access to your Google Geocoding API Account by adding the IP/host of the server to the list of Application restrictions.
Encrypt the API key using NNL_HOME/install/nnl-encrypt-password.sh.
For more information, see Step 4: Encrypt Credentials in the Linux installation instructions.
Use nnl-mgmt.sh to assign values to the tenant-specific property nnl.geo.coder.google.api.key:
./nnl-mgmt.sh properties set -tenantid <tenantID> -name nnl.geo.coder.google.api.key -value <Encrypted-API-key-value>